Possible trojan or something
Hi all - first I want to say thanks in advance to anyone who can help. Second, I have little to no idea what I'm doing, so forgive a giant dump of info but hoping someone on here can help. I think I have adware or spyware or something not right on my MacBook Air.
It's been acting a little weird for a while - maybe because its 4 or 5 years old or maybe because there has been something on it for a long time and i didn't realize it. For quite a while, I've noticed the little beach ball pinwheel thing popping up more than normal when I'm online. Also, there's something wrong with the mousepad on my computer and I have to press down very hard to scroll or do anything (i.e. cut and paste a sentence - my fingertips get swollen because I need to press so hard). But the severity of the problem got worse tonight. I was doing research on ISIS propaganda videos for an article, and went to a website listed on the first page of google for some version of that search term. I went on, clicked on a video and a big gray message popped up saying I was infected and to call some number - I couldn't X it out or do anything so immediately shut down my computer using the power key. Obviously - I didn't call the number.
I turned it back on and started noticing infolinks and excessive popups everywhere. My already sort of slow Mac is way worse. That rainbow pinwheel pops up every time I click on anything now, especially when I use sidebars to scroll. There's a huge delay between typing a word and it showing up on the screen - especially while searching on Goolge. Everything is just acting weird. I've been searching various forums for the past few hours - and below is the result of everything that showed up in terminal. Can anyone take a look and see if any of the files don't look right? I was actively searching for the flashback and ventir trojans, as well as key loggers. One file of concern is softRAID.kext. And some of the adobe files.
Oh - I also tried to search in terminal for files I know are malicious, and anytime I tried searching - permission was denied. I'll include an example of that below. Anyway, thanks so much to anyone who can help!
Last login: Sat Oct 10 03:01:55 on ttys000
rebekahs-MacBook-Air:~ rebekah$ kextstat -kl | awk '!/com\.apple/{printf "%s %s\n", $6, $7}'
rebekahs-MacBook-Air:~ rebekah$ sudo launchctl list | sed 1d | awk '!/0x|com\.(apple|openssh|vix)|edu\.mit|org\.(amavis|apache|cups|isc|ntp|postfi x|x)/{print $3}'
Password:
com.microsoft.office.licensing.helper
com.adobe.SwitchBoard
com.adobe.fpsaud
com.adobe.adobeupdatedaemon
rebekahs-MacBook-Air:~ rebekah$ launchctl list | sed 1d | awk '!/0x|com\.apple|edu\.mit|org\.(x|openbsd)/{print $3}'
com.microsoft.autoupdate.fba.43856
com.microsoft.Office365Service.53712
com.microsoft.Word.29600
com.adobe.PDApp.AAMUpdatesNotifier.34352.8D5AA5B6-B5CA-4A99-9794-415CE851993A
com.google.Chrome.52656
com.evernote.EvernoteHelper.45616
com.google.GoogleDrive.25376
com.github.GitHub.Conduit
com.adobe.AdobeCreativeCloud
com.google.keystone.user.agent
com.adobe.ARM.202f4087f2bbde52e3ac2df389f53a4f123223c9cc56a8fd83a6f7ae
com.adobe.AAM.Scheduler-1.0
rebekahs-MacBook-Air:~ rebekah$ ls -1A /e*/mach* {,/}L*/{Ad,Compon,Ex,Fram,In,Keyb,La,Mail/Bu,P*P,Priv,Qu,Scripti,Servi,Spo,Sta} * L*/Fonts 2> /dev/null
/Library/Components:
/Library/Extensions:
ATTOCelerityFC8.kext
ATTOExpressSASHBA2.kext
ATTOExpressSASRAID2.kext
ArcMSR.kext
CalDigitHDProDrv.kext
HighPointIOP.kext
HighPointRR.kext
PromiseSTEX.kext
SoftRAID.kext
/Library/Frameworks:
AEProfiling.framework
AERegistration.framework
AudioMixEngine.framework
NyxAudioAnalysis.framework
PluginManager.framework
iTunesLibrary.framework
/Library/Input Methods:
/Library/Internet Plug-Ins:
AdobeAAMDetect.plugin
AdobePDFViewer.plugin
AdobePDFViewerNPAPI.plugin
Default Browser.plugin
Flash Player.plugin
JavaAppletPlugin.plugin
Quartz Composer.webplugin
QuickTime Plugin.plugin
SharePointBrowserPlugin.plugin
SharePointWebKitPlugin.webplugin
Silverlight.plugin
flashplayer.xpt
nsIQTScriptablePlugin.xpt
/Library/Keyboard Layouts:
/Library/LaunchAgents:
com.adobe.AAM.Updater-1.0.plist
com.adobe.AdobeCreativeCloud.plist
/Library/LaunchDaemons:
com.adobe.SwitchBoard.plist
com.adobe.adobeupdatedaemon.plist
com.adobe.fpsaud.plist
com.microsoft.office.licensing.helper.plist
/Library/PreferencePanes:
Flash Player.prefPane
/Library/PrivilegedHelperTools:
Google Drive Icon Helper
com.microsoft.office.licensing.helper
/Library/QuickLook:
iBooksAuthor.qlgenerator
iWork.qlgenerator
/Library/QuickTime:
AppleIntermediateCodec.component
AppleMPEG2Codec.component
/Library/ScriptingAdditions:
Adobe Unit Types.osax
/Library/Spotlight:
Microsoft Office.mdimporter
iBooksAuthor.mdimporter
iWork.mdimporter
/Library/StartupItems:
/etc/mach_init.d:
/etc/mach_init_per_login_session.d:
/etc/mach_init_per_user.d:
Library/Address Book Plug-Ins:
SkypeABDialer.bundle
SkypeABSMS.bundle
Library/Fonts:
Library/Input Methods:
.localized
Library/Internet Accounts:
V1
Library/Internet Plug-Ins:
CitrixOnlineWebDeploymentPlugin.plugin
Picasa.plugin
Library/Keyboard Layouts:
Library/LaunchAgents:
.DS_Store
com.adobe.AAM.Updater-1.0.plist
com.adobe.ARM.202f4087f2bbde52e3ac2df389f53a4f123223c9cc56a8fd83a6f7ae.plist
com.google.keystone.agent.plist
Library/PreferencePanes:
Library/Services:
.localized
rebekahs-MacBook-Air:~ rebekah$ osascript -e 'tell application "System Events" to get name of every login item' 2> /dev/null
iTunesHelper, Google Drive, Hotspot Shield, AdobeResourceSynchronizer, CrossOver CD Helper, EvernoteHelper
rebekahs-MacBook-Air:~ rebekah$
Ex of permissions denied and another search:
rebekahs-MacBook-Air:~ rebekah$ defaults write com.apple.finder AppleShowAllFiles TRUE
rebekahs-MacBook-Air:~ rebekah$ killall Finder
rebekahs-MacBook-Air:~ rebekah$ defaults write com.apple.finder AppleShowAllFiles TRUE
rebekahs-MacBook-Air:~ rebekah$ defaults write com.apple.finder AppleShowAllFiles TRUE
rebekahs-MacBook-Air:~ rebekah$ defaults write com.apple.finder AppleShowAllFiles FALSE
rebekahs-MacBook-Air:~ rebekah$ killall Finder
rebekahs-MacBook-Air:~ rebekah$ find "/" -name "updated.kext"
find: /.DocumentRevisions-V100: Permission denied
find: /.fseventsd: Permission denied
find: /.MobileBackups: Permission denied
find: /.Spotlight-V100: Permission denied
find: /.Trashes: Permission denied
find: /dev/fd/3: Not a directory
find: /dev/fd/4: Not a directory
find: /Library/Application Support/Apple/ParentalControls/Users: Permission denied
find: /Library/Application Support/com.apple.TCC: Permission denied
find: /Library/Caches/com.apple.Spotlight/schema.501.plist: Permission denied
find: /Library/Caches/com.apple.Spotlight/schema.502.plist: Permission denied
MacBook Air (13-inch Mid 2012), Virus, tojans, spyware